Privacy policy

Shinun / שינון · com.benbasha.shinun · last updated 20 September 2026

In short: no account, no sign-up. Your decks and cards are stored on your device. There are no ads and no cross-app tracking. Anonymous, aggregated usage and crash data help fix bugs and improve the app. The one time your content leaves the device is when you tap Share on a deck. That uploads a read-only copy so the person you send the link to can open it.

מדיניות הפרטיות בעברית

What the app is

Shinun is an offline flashcard app with spaced repetition (FSRS). You create or import decks, study them in several modes, and the scheduler decides what you see next. There are no user accounts, no social feed, no ads, and no server that holds your study data.

Data that stays on your device

Stored locally and never uploaded to us:

  • your decks and cards (both faces, any extra note, tags);
  • your review history and scheduling state (FSRS parameters, due dates, lapses);
  • your study sessions (start/end time, mode, counts);
  • your settings: theme, language, study preferences, TTS on/off, the premium entitlement flag, and local kill switches;
  • the home-screen / Lock-Screen widget snapshot, which is written to an App Group container on the same device.

Uninstalling the app deletes all of it. There is no cloud copy for us to restore, and no “sign in on a new phone” path.

For completeness: the local database and the preference store are not encrypted at rest by the app. The device’s own disk encryption is what protects them.

Sharing a deck (the only content upload, and only if you ask for it)

When, and only when, you tap Share on a deck, the app uploads a read-only snapshot of that deck to Google Firebase (Cloud Firestore) and gives you a link: https://shinun.benbasha.com/d/<id>.

  • What is uploaded: the deck’s name, its two language/direction settings, and its cards (front, back, optional extra note), plus a card count, a timestamp, and the app version. Nothing else. There is no name, no email, no device identifier and no user id inside the document.
  • Why it is authenticated anonymously: the write requires Firebase Anonymous Authentication. That is a rate-limiting and abuse-protection handle, not an identity: it lets Firebase see “a caller” so the rules can refuse floods. The anonymous id is generated on the device, is not tied to you, and is not stored inside the shared document.
  • Who can read it: anyone who has the link. The id is 10 random base62 characters (~59 bits), and the security rules allow fetching a document by id only. The collection cannot be listed, so there is no way to browse other people’s shares.
  • It cannot be edited or deleted from the app. A snapshot is a photograph: by design the rules deny updates and deletes, so what you sent stays what you sent, and edits you make afterwards stay with you. If you need a snapshot removed, email shinun@benbasha.com with the link.
  • Receiving a link downloads the snapshot and previews it; nothing enters your library until you accept, and what you then get is your own local copy.
  • Do not share decks containing information you would not put on a public web page. A link is the only protection, and links get forwarded.
  • Size limits (2,000 cards, 200 KB) are enforced both in the app and in the security rules; oversized decks are exported as a file instead.

Anonymous usage and crash data

To understand which features are used and to fix crashes, the app sends anonymous, aggregated events to Mixpanel and to Google Firebase (Google Analytics for Firebase + Crashlytics). These providers process the data on our behalf; we do not sell it and we do not share it for anyone else’s purposes.

What these events carry (this list is the allowlist the code enforces):

  • counts and durations: how many cards were in a session, how long it took, how many cards an import produced;
  • kinds and modes: which study mode, which import source, which paywall trigger, which failure reason code;
  • app state: app version, OS version, device model, interface language;
  • a random, app-scoped installation identifier generated by the analytics SDKs (Firebase’s app-instance id, Mixpanel’s distinct id). It is not the advertising id, it is not shared with anyone, and it is reset when you reinstall.

What they never carry: card text, deck names, imported file contents, typed answers, file names, or any free text you wrote. Import failures report a reason code, never a line of your file. This is enforced by sanitize() in the app’s analytics layer, not merely by convention.

There is no advertising identifier: the Android build strips the AD_ID permissions, there is no App Tracking Transparency prompt because the app never tracks, and no ad SDK is present.

Purchases

Shinun is free with one optional, one-time purchase (shinun_premium) that unlocks the paid features. Payment is handled entirely by Apple and Google; we never see your card, your billing address or your Apple/Google account. The app stores only a local flag saying the purchase is active. Note that Google Analytics for Firebase automatically records an in-app-purchase event for store transactions, so purchase history is listed in our store data declarations even though our own code does not send it.

What the app does NOT collect

No name, email address, phone number or postal address. No precise location: the app has no location permission and no GPS access. Google Analytics for Firebase derives an approximate, city-level location from your IP address (the IP is masked and not stored); Mixpanel’s IP geolocation is turned off. No contacts, calendar, photos, microphone or camera access. No health data. No browsing or search history. No advertising identifier. No cross-app or cross-site tracking of any kind.

Children

Shinun is a general-audience study app, not directed at children. On Google Play its target age group is 13 and over. It is not a Families-programme app and contains no child-directed content.

Your choices and your rights

  • Stop all local storage: delete the app; everything local goes with it.
  • Stop analytics: the app has no in-app analytics toggle today. You can use your OS-level controls (iOS: Settings → Privacy & Security → Analytics & Improvements / “Allow Apps to Request to Track”, which Shinun never asks for; Android: Settings → Google → Ads). If you want your anonymous analytics records purged, email shinun@benbasha.com and say so.
  • Remove a shared deck: email shinun@benbasha.com with the link.
  • Access / deletion requests (GDPR, CCPA and similar): email shinun@benbasha.com. Because there is no account, we usually cannot find “your” data without something to match on (a share link, an approximate time), and in most cases there is nothing of yours on our side at all.

Data deletion

There is no account to delete. Uninstalling the app deletes every piece of study data, because all of it lives on the device. The only data that can exist off the device is a deck snapshot you chose to share; email shinun@benbasha.com with the link and it will be removed. Analytics records are anonymous and aggregated and are retained by the providers under their own retention schedules (Firebase: up to 14 months for event data; Mixpanel: the project’s retention window).

Sub-processors

ProviderWhat it processesWhere
Google Firebase (Analytics, Crashlytics)anonymous usage + crash eventsGoogle Cloud (US)
Google Cloud Firestoredeck snapshots you chose to shareGoogle Cloud (US, nam5)
Mixpanelanonymous usage eventsUS data residency
Apple / Googlepurchase processingtheir own terms

Changes

If this policy changes materially, the app’s store listing and this page are updated and the date at the top changes.

Contact

shinun@benbasha.com

מדיניות פרטיות

שינון · com.benbasha.shinun · עודכן לאחרונה ב-20 בספטמבר 2026

בקצרה: אין חשבון ואין הרשמה. החפיסות והכרטיסים שלכם נשמרים על המכשיר. אין פרסומות ואין מעקב חוצה־אפליקציות. לשיפור האפליקציה ולתיקון קריסות נאספים נתוני שימוש אנונימיים ומצטברים בלבד. הפעם היחידה שבה תוכן שלכם עוזב את המכשיר היא כשאתם עצמכם לוחצים ״שיתוף״ על חפיסה. אז נשמר עותק לקריאה בלבד, כדי שמי שקיבל את הקישור יוכל לפתוח אותו.

Read the policy in English

מה האפליקציה

שינון היא אפליקציית כרטיסיות שעובדת אופליין, עם חזרה מרווחת (FSRS). יוצרים או מייבאים חפיסות, לומדים בכמה מצבים, והמתזמן מחליט מה תראו בפעם הבאה. אין חשבונות משתמש, אין פיד חברתי, אין פרסומות, ואין שרת שמחזיק את נתוני הלמידה שלכם.

מידע שנשמר רק במכשיר שלכם

  • החפיסות והכרטיסים (שני הצדדים, הערה נוספת, תגיות);
  • היסטוריית החזרות ומצב התזמון (פרמטרי FSRS, תאריכי יעד, שכחות);
  • מפגשי הלימוד (זמני התחלה וסיום, מצב, ספירות);
  • ההגדרות: ערכת נושא, שפה, העדפות לימוד, הקראה, סטטוס הרכישה, ומתגי כיבוי מקומיים;
  • תמונת המצב של הווידג׳ט, שנכתבת ל-App Group על אותו מכשיר.

הסרת האפליקציה מוחקת את כל זה. אין לנו עותק בענן, ואין מסלול של ״התחברות במכשיר חדש״.

לשם הדיוק: מסד הנתונים המקומי ומאגר ההעדפות אינם מוצפנים בידי האפליקציה. ההצפנה של הדיסק במכשיר היא מה שמגן עליהם.

שיתוף חפיסה: ההעלאה היחידה, ורק אם ביקשתם

כשאתם לוחצים שיתוף על חפיסה, ורק אז, האפליקציה מעלה תמונת מצב לקריאה בלבד של אותה חפיסה ל-Google Firebase‏ (Cloud Firestore) ומחזירה קישור: https://shinun.benbasha.com/d/<id>.

  • מה נשלח: שם החפיסה, הגדרות השפה והכיוון שלה, והכרטיסים (צד קדמי, צד אחורי, הערה אופציונלית), בתוספת מספר כרטיסים, חותמת זמן וגרסת האפליקציה. שום דבר אחר. אין במסמך שם, אימייל, מזהה מכשיר או מזהה משתמש.
  • למה נדרשת הזדהות אנונימית: הכתיבה דורשת Firebase Anonymous Authentication. זהו אמצעי להגבלת קצב ולמניעת ניצול לרעה, לא זהות. הוא מאפשר ל-Firebase לראות ״פונה״ כלשהו. המזהה נוצר על המכשיר, אינו מקושר אליכם, ואינו נשמר בתוך המסמך המשותף.
  • מי יכול לקרוא: כל מי שיש לו הקישור. המזהה הוא 10 תווים אקראיים (בערך 59 ביט), והכללים מתירים שליפה לפי מזהה בלבד. אי אפשר לרשום את האוסף, ולכן אי אפשר לדפדף בשיתופים של אחרים.
  • אי אפשר לערוך או למחוק מתוך האפליקציה. תמונת מצב היא צילום: הכללים אוסרים עדכון ומחיקה במכוון, כך שמה ששלחתם נשאר מה ששלחתם. להסרה, כתבו ל-shinun@benbasha.com עם הקישור.
  • קבלת קישור מורידה את תמונת המצב ומציגה תצוגה מקדימה; שום דבר לא נכנס לספרייה שלכם עד שתאשרו, ומה שמתקבל הוא עותק מקומי שלכם.
  • אל תשתפו חפיסות עם מידע שלא הייתם מפרסמים בדף אינטרנט פתוח. הקישור הוא ההגנה היחידה, וקישורים מועברים הלאה.
  • מגבלות הגודל (2,000 כרטיסים, 200KB) נאכפות גם באפליקציה וגם בכללי האבטחה; חפיסה גדולה מדי מיוצאת כקובץ במקום.

נתוני שימוש וקריסות אנונימיים

כדי להבין אילו יכולות בשימוש ולתקן קריסות, האפליקציה שולחת אירועים אנונימיים ומצטברים ל-Mixpanel ול-Google Firebase‏ (Google Analytics for Firebase ו-Crashlytics). ספקים אלה מעבדים את הנתונים עבורנו; איננו מוכרים אותם.

האירועים נושאים ספירות ומשכים, סוגים ומצבים (מצב לימוד, מקור ייבוא, טריגר של מסך רכישה, קוד סיבה לכשל), מצב האפליקציה (גרסה, מערכת הפעלה, דגם, שפת ממשק), ומזהה התקנה אקראי של ערכות הפיתוח. הם לעולם לא נושאים טקסט של כרטיס, שמות חפיסות, תוכן של קבצים מיובאים או תשובות שהקלדתם. הדבר נאכף בקוד, לא רק בהבטחה.

אין מזהה פרסומי: גרסת האנדרואיד מסירה את הרשאות ה-AD_ID, אין בקשת מעקב ב-iOS כי האפליקציה לא עוקבת, ואין בה ערכת פיתוח של פרסום.

רכישות

האפליקציה חינמית עם רכישה חד־פעמית אופציונלית (shinun_premium). התשלום מטופל כולו על ידי Apple ו-Google; איננו רואים את פרטי האשראי שלכם. האפליקציה שומרת רק דגל מקומי. שימו לב ש-Google Analytics for Firebase רושם אוטומטית אירוע רכישה, ולכן היסטוריית רכישות מופיעה בהצהרות החנות.

מה האפליקציה לא אוספת

אין שם, אימייל, טלפון או כתובת. אין מיקום מדויק: לאפליקציה אין הרשאת מיקום ואין גישה ל-GPS. Google Analytics for Firebase מסיק מיקום משוער, ברמת עיר, מכתובת ה-IP (הכתובת מוסתרת ולא נשמרת); איתור המיקום לפי IP של Mixpanel כבוי. אין אנשי קשר, יומן, תמונות, מיקרופון או מצלמה. אין נתוני בריאות. אין היסטוריית גלישה או חיפוש. אין מזהה פרסומי. אין מעקב חוצה־אפליקציות.

ילדים

שינון היא אפליקציית לימוד לקהל הרחב ואינה מיועדת לילדים. ב-Google Play קבוצת הגיל היא 13 ומעלה. אינה חלק מתוכנית ה-Families.

הבחירות והזכויות שלכם

  • להפסיק כל אחסון מקומי: מוחקים את האפליקציה, והכול הולך איתה.
  • להפסיק אנליטיקה: אין באפליקציה מתג אנליטיקה כרגע. אפשר להשתמש בבקרות של מערכת ההפעלה, ואם תרצו שהרשומות האנונימיות שלכם יימחקו, כתבו ל-shinun@benbasha.com.
  • להסיר חפיסה משותפת: כתבו ל-shinun@benbasha.com עם הקישור.
  • בקשות עיון ומחיקה (GDPR, CCPA ודומיהן): כתבו ל-shinun@benbasha.com. מכיוון שאין חשבון, בדרך כלל אי אפשר לאתר ״את המידע שלכם״ בלי משהו להצליב מולו (קישור שיתוף, זמן משוער), וברוב המקרים אין אצלנו שום דבר ששייך לכם.

מחיקת מידע

אין חשבון למחוק. הסרת האפליקציה מוחקת את כל נתוני הלמידה, כי כולם נמצאים על המכשיר. המידע היחיד שעשוי להתקיים מחוץ למכשיר הוא תמונת מצב של חפיסה שאתם בחרתם לשתף; כתבו ל-shinun@benbasha.com עם הקישור והיא תוסר. רשומות האנליטיקה אנונימיות ונשמרות אצל הספקים לפי לוחות הזמנים שלהם (Firebase: עד 14 חודשים לאירועים; Mixpanel: חלון השמירה של הפרויקט).

מעבדי משנה

ספקמה הוא מעבדהיכן
Google Firebase‏ (Analytics, Crashlytics)אירועי שימוש וקריסות אנונימייםGoogle Cloud‏ (ארה״ב)
Google Cloud Firestoreתמונות מצב של חפיסות שבחרתם לשתףGoogle Cloud‏ (ארה״ב, nam5)
Mixpanelאירועי שימוש אנונימייםארה״ב
Apple / Googleעיבוד תשלומיםהתנאים שלהם

שינויים

אם המדיניות תשתנה באופן מהותי, דף החנות והדף הזה יתעדכנו והתאריך בראש הדף ישתנה.

יצירת קשר

shinun@benbasha.com